Compliance matrix
Digital Operational Resilience Act
European Union · Updated 2026-07-19
Applies to: EU financial entities and their critical ICT third-party providers.
Requirements mapped to CIAM
ICT access control and authentication
Access to critical financial systems must use strong authentication and least privilege.
CIAM controls
- MFA and phishing-resistant authentication for privileged access
- Least-privilege, reviewed access
Evidence
- Access control policy
- Access reviews
Ask the vendor
- Can we enforce phishing-resistant MFA and least-privilege access for critical systems?
ICT incident detection and reporting
Identity-related incidents must be detected, logged, and reported within regulatory timelines.
CIAM controls
- Monitoring and alerting on identity anomalies
- Exportable audit logs for incident reporting
Evidence
- Incident logs
- Monitoring configuration
Ask the vendor
- What identity monitoring and audit export support incident reporting?
Third-party ICT risk (identity providers)
Your CIAM vendor is a third-party ICT provider whose resilience and exit strategy you must manage.
CIAM controls
- Documented resilience and SLAs
- Exit / portability plan for the identity provider
Evidence
- Vendor resilience documentation
- Exit plan
Ask the vendor
- What are your availability SLAs, and how portable is our user and configuration data on exit?
Take this into procurement
Turn these requirements into vendor questions.
The vendor questions above map directly into an RFP or an evaluation checklist you can share with security and procurement.
Where it bites hardest
FAQ
- Is a CIAM vendor in DORA scope?
- If your CIAM platform supports critical financial functions it is a third-party ICT provider under DORA, so its resilience, SLAs, incident handling, and your exit/portability plan all become part of your compliance. Strong authentication and audit logging for critical systems are the core CIAM controls.
Source
Regulation (EU) 2022/2554 (DORA, EUR-Lex)
This matrix is practitioner guidance, not legal advice, and does not establish an attorney-client relationship. Confirm your obligations with qualified counsel. See our disclaimer.